VendorsSamsungandroid16.0
Vulnerabilities

Samsung Android 9.0 16.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

105CVEs
CVE-2025-58478
Out-of-bounds write in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bounds memory.
Published 2025-12-02 · Analyzed
7.5EPSS 0.003
CVE-2026-21058
Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts' privilege.
Published 2026-08-10 · Analyzed
7.1EPSS 0.001
CVE-2025-21080
Improper export of android application components in Dynamic Lockscreen prior to SMR Dec-2025 Release 1 allows local attackers to access files with Dynamic Lockscreen's privilege.
Published 2025-12-02 · Analyzed
7.1EPSS 0.001
CVE-2026-21104
Heap-based buffer overflow in KnoxVault trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute arbitrary code.
Published 2026-09-09 · Analyzed
7.1EPSS 0.001
CVE-2026-21059
Improper export of android application components in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts' privilege.
Published 2026-08-10 · Analyzed
7.1EPSS 0.001
CVE-2026-21100
Improper access control in SystemUI prior to SMR Sep-2026 Release 1 allows local attackers to launch arbitrary activity.
Published 2026-09-09 · Analyzed
7.1EPSS 0.001
CVE-2026-20980
Improper input validation in PACM prior to SMR Feb-2026 Release 1 allows physical attacker to execute arbitrary commands.
Published 2026-02-04 · Analyzed
7.0EPSS 0.002
CVE-2026-21064
Improper access control in Weaver prior to SMR Aug-2026 Release 1 allows local attackers to cause device inoperability.
Published 2026-08-10 · Analyzed
7.0EPSS 0.001
CVE-2026-20977
Improper access control in Emergency Sharing prior to SMR Feb-2026 Release 1 allows local attackers to interrupt its functioning.
Published 2026-02-04 · Analyzed
6.9EPSS 0.001
CVE-2026-21023
Insufficient verification of data authenticity in PackageManagerService prior to SMR Mar-2026 Release 1 allows local attackers to modify the installation restriction of specific application.
Published 2026-04-29 · Analyzed
6.9EPSS 0.001
CVE-2026-21025
Incorrect privilege assignment in Telephony prior to SMR Jun-2026 Release 1 allows local attackers to access sensitive information.
Published 2026-06-05 · Analyzed
6.9EPSS 0.001
CVE-2026-21022
Improper handling of insufficient permissions in Routines prior to SMR May-2026 Release 1 allows local attackers to access sensitive information.
Published 2026-05-13 · Analyzed
6.9EPSS 0.001
CVE-2026-20982
Path traversal in ShortcutService prior to SMR Feb-2026 Release 1 allows privileged local attacker to create file with system privilege.
Published 2026-02-04 · Analyzed
6.8EPSS 0.003
CVE-2026-21009
Improper check for exceptional conditions in Recents prior to SMR Apr-2026 Release 1 allows physical attacker to bypass App Pinning.
Published 2026-04-13 · Analyzed
6.8EPSS 0.002
CVE-2026-21021
Improper input validation in Routines prior to SMR May-2026 Release 1 allows physical attackers to launch privileged activity.
Published 2026-05-13 · Analyzed
6.8EPSS 0.002
CVE-2025-21073
Insecure default configuration in USB connection mode prior to SMR Nov-2025 Release 1 allows privileged physical attackers to access user data. User interaction is required for triggering this vulnerability.
Published 2025-11-05 · Analyzed
6.8EPSS 0.002
CVE-2025-21047
Improper access control in KnoxGuard prior to SMR Oct-2025 Release 1 allows physical attackers to use the privileged APIs.
Published 2025-10-10 · Analyzed
6.8EPSS 0.002
CVE-2026-21103
Path traversal in GalaxyDiagnostics prior to SMR Sep-2026 Release 1 allows physical attackers to access files with system privilege.
Published 2026-09-09 · Analyzed
6.8EPSS 0.002
CVE-2026-21003
Improper input validation in data related to network restrictions prior to SMR Apr-2026 Release 1 allows physical attackers to bypass the restrictions.
Published 2026-04-13 · Analyzed
6.8EPSS 0.002
CVE-2026-21007
Improper check for exceptional conditions in Device Care prior to SMR Apr-2026 Release 1 allows physical attackers to bypass Knox Guard.
Published 2026-04-13 · Analyzed
6.8EPSS 0.002
CVE-2026-21018
Out-of-bounds write in SveService prior to SMR May-2026 Release 1 allows local privileged attackers to execute arbitrary code.
Published 2026-05-13 · Analyzed
6.8EPSS 0.002
CVE-2026-21011
Incorrect privilege assignment in Bluetooth in Maintenance mode prior to SMR Apr-2026 Release 1 allows physical attackers to bypass Extend Unlock.
Published 2026-04-13 · Analyzed
6.8EPSS 0.001
CVE-2026-21063
Improper export of android application components in AppLock prior to SMR Aug-2026 Release 1 allows physical attackers to bypass app lock function.
Published 2026-08-10 · Analyzed
6.8EPSS 0.001
CVE-2025-21031
Improper access control in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to use the privileged APIs.
Published 2025-09-03 · Analyzed
6.8EPSS 0.001
CVE-2026-21012
External control of file name in AODManager prior to SMR Apr-2026 Release 1 allows privileged local attacker to create file with system privilege.
Published 2026-04-13 · Analyzed
6.8EPSS 0.001
CVE-2026-21015
Incorrect default permissions in FactoryCamera prior to SMR May-2026 Release 1 allows local attacker to access unique identifier.
Published 2026-05-13 · Analyzed
6.8EPSS 0.001
CVE-2026-20988
Improper verification of intent by broadcast receiver in Settings prior to SMR Mar-2026 Release 1 allows local attacker to launch arbitrary activity with Settings privilege. User interaction is required for triggering this vulnerability.
Published 2026-03-16 · Analyzed
6.8EPSS 0.001
CVE-2026-20968
Use after free in DualDAR prior to SMR Jan-2026 Release 1 allows local privileged attackers to execute arbitrary code.
Published 2026-01-09 · Analyzed
6.7EPSS 0.002
CVE-2026-21060
Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows physical attackers to access data across multiple user profiles.
Published 2026-08-10 · Analyzed
6.7EPSS 0.002
CVE-2026-21097
Improper authentication in ActivityTaskManagerService prior to SMR Sep-2026 Release 1 allows local privileged attackers to launch arbitrary activity.
Published 2026-09-09 · Analyzed
6.7EPSS 0.001
CVE-2026-20991
Improper privilege management in ThemeManager prior to SMR Mar-2026 Release 1 allows local privileged attackers to reuse trial contents.
Published 2026-03-16 · Analyzed
6.7EPSS 0.001
CVE-2026-21093
Stack-based buffer overflow in PROCA trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to write out-of-bounds memory.
Published 2026-09-09 · Analyzed
6.7EPSS 0.001
CVE-2026-20981
Improper input validation in FacAtFunction prior to SMR Feb-2026 Release 1 allows privileged physical attacker to execute arbitrary command with system privilege.
Published 2026-02-04 · Analyzed
6.6EPSS 0.002
CVE-2026-21061
Improper input validation in Samsung Dialer prior to SMR Aug-2026 Release 1 allows remote attackers to access SIM related functions. User interaction is required for triggering this vulnerability.
Published 2026-08-10 · Analyzed
6.5EPSS 0.003
CVE-2025-58477
Out-of-bounds write in parsing IFD tag in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bounds memory.
Published 2025-12-02 · Analyzed
6.5EPSS 0.003
CVE-2026-21008
Exposure of sensitive information in S Share prior to SMR Apr-2026 Release 1 allows adjacent attacker to access sensitive information.
Published 2026-04-13 · Analyzed
6.5EPSS 0.002
CVE-2026-21026
Improper export of android application components in SpriteWallpaper prior to SMR Jun-2026 Release 1 allows local attackers to access to sensitive information.
Published 2026-06-05 · Analyzed
6.4EPSS 0.001
CVE-2026-21073
Improper input validation in Galaxy Themes prior to SMR Aug-2026 Release 1 allows physical attackers to launch arbitrary activity.
Published 2026-08-10 · Analyzed
6.1EPSS 0.002
CVE-2026-20978
Improper authorization in KnoxGuardManager prior to SMR Feb-2026 Release 1 allows local attackers to bypass the persistence configuration of the application.
Published 2026-02-04 · Analyzed
6.1EPSS 0.001
CVE-2025-21010
Improper privilege management in SamsungAccount prior to SMR Aug-2025 Release 1 allows local privileged attackers to deactivate Samsung account.
Published 2025-08-06 · Analyzed
6.0EPSS 0.001
← Prev2 / 3Next →